ProductsIntelligencePricingMethodologyContact
Cresthaven AnalyticsIntelligence Brief

EU EBA Banking Brief

July 9, 2026·European Banking Authority·EU

EBA publishes final technical package for reporting framework version 4.3 covering Third-Country Branches and AMLA risk assessment data collection

On July 9, 2026, the EBA published the final technical package for version 4.3 of its reporting framework. The package implements new reporting requirements for Third-Country Branches under the Capital Requirements Directive and supports AMLA's risk assessment data collection exercise.

The version 4.3 package creates binding technical specifications that EU-supervised institutions with Third-Country Branch structures must implement for prudential reporting under the Capital Requirements Directive. The same package operationalizes AMLA's risk assessment data collection, placing AML supervisory reporting inside the same standardized infrastructure as prudential returns. Institutions that operate across both perimeters carry a combined implementation obligation: taxonomy alignment, validation rule updates, and structured AML risk data production under a single framework release.

  • Third-Country Branches Face New Prudential Reporting Obligations: Credit institutions operating Third-Country Branches in the EU must now implement the version 4.3 technical specifications. Firms running TCB structures need to assess their data architecture and reporting pipelines against the new templates before the applicable submission date.
  • AMLA Data Collection Enters the Supervisory Infrastructure: The framework embeds AMLA's risk assessment data collection directly into the EBA's standardized reporting architecture. Institutions subject to AMLA oversight carry a concrete obligation to produce structured AML risk data in a format aligned with the new technical package.
  • IT and Data Teams Carry the Implementation Load: Version 4.3 constitutes a formal taxonomy and validation update. Firms using vendor reporting solutions or in-house XBRL pipelines must validate their systems against the released data point model, taxonomy files, and validation rules before go-live.
  • Dual Regulatory Perimeter in a Single Package: The package bridges prudential reporting under the Capital Requirements Directive and AML supervisory data collection under the new AMLA regime. Compliance functions must coordinate across both prudential and financial crime frameworks to meet the combined requirements.

- Earlier versions in the EBA's 4.0 series addressed prudential consolidation and market risk. Version 4.3 is the first package to formally integrate AMLA supervisory data collection into the standardized reporting infrastructure.

- The principal structural departure is the dual-perimeter design: a single technical package now carries obligations under both the Capital Requirements Directive and the EU AML Authority regime simultaneously.

- AMLA became operational on July 1, 2025, and is now executing its first supervisory data collection cycle. This package is the technical instrument through which that collection reaches reporting institutions.

HIGH — A final technical package constituting binding reporting specifications with sector-wide application; EU credit institutions with Third-Country Branch structures and institutions subject to AMLA oversight must update taxonomy, validation rules, and data pipelines to comply.

Monitor the EBA and AMLA for the confirmed go-live date for version 4.3 submissions and for any supplementary Q&A or implementation guidance issued in connection with this reporting framework.